Privacy Policy
Last updated: May 2026
1. Who we are
Leethack (“we”, “us”, or “our”) operates the leethack.io platform — a gamified secure-coding training service. This policy explains what personal data we collect, how we use it, and your rights over it.
Questions? Email us at privacy@leethack.io.
2. Data we collect
2.1 Account data (OAuth sign-in)
When you sign in with Google or GitHub we receive your name, email address, and profile picture from that provider. We store only what is necessary to create and maintain your account. We do not receive or store your OAuth provider password.
2.2 Usage data
We record which challenges you view, run, and submit, your pass/fail results, XP earned, and time-on-challenge. This is used to power your dashboard, track progress, and improve the platform.
2.3 Code submissions
Code you write in the editor is sent to our backend for test execution and stored as part of your submission history. We do not share your submission code with third parties, train AI models on it, or publish it publicly.
2.4 Analytics
We use PostHog to collect anonymised usage events (page views, feature interactions). PostHog does not receive your name or email. You can opt out via your browser’s Do Not Track setting — we honour it.
2.5 Error monitoring
We use Sentry to capture application errors. Sentry may record your IP address and a partial browser fingerprint alongside the error context. No submission code is included in error reports.
2.6 Infrastructure
The frontend is hosted on Vercel and the backend on Fly.io. Both providers process request metadata (IP address, user-agent, timestamps) as part of normal operation. See their respective privacy policies for details.
3. How we use your data
- Authenticate you and maintain your session
- Display your name and avatar in the app
- Track your XP, streak, and challenge progress
- Run your code submissions in a sandboxed environment
- Diagnose errors and improve platform reliability
- Send transactional emails (account events only — no marketing without consent)
4. Legal basis (GDPR)
For users in the European Economic Area (EEA) we process your data under the following legal bases:
- Contract performance — account creation, authentication, and delivering the service you signed up for.
- Legitimate interests — error monitoring and platform analytics (subject to your Do Not Track preference).
- Consent — any future marketing communications (opt-in only).
5. Data retention
We keep your account data for as long as your account is active. Submission history is retained indefinitely so your progress is preserved. If you delete your account, all associated personal data is permanently removed within 30 days.
6. Your rights
Depending on your jurisdiction you may have the right to:
- Access — request a copy of the personal data we hold about you.
- Correction — ask us to fix inaccurate data.
- Deletion — request that we delete your account and associated data.
- Portability — receive your data in a machine-readable format.
- Objection — object to processing based on legitimate interests.
To exercise any of these rights email privacy@leethack.io from the address associated with your account. We will respond within 30 days.
7. Third-party services
| Service | Purpose | Privacy policy |
|---|---|---|
| Google OAuth | Sign-in | policies.google.com |
| GitHub OAuth | Sign-in | github.com |
| Vercel | Frontend hosting | vercel.com |
| Fly.io | Backend hosting | fly.io |
| PostHog | Analytics | posthog.com |
| Sentry | Error monitoring | sentry.io |
8. Cookies
We use a single session cookie to keep you logged in (HttpOnly, Secure, SameSite=Lax). We do not use advertising or tracking cookies. PostHog uses localStorage for anonymous event deduplication.
9. Changes to this policy
We may update this policy as the platform evolves. Material changes will be announced via the email associated with your account at least 14 days before taking effect. Continued use of the platform after that date constitutes acceptance.